Spyware / Malware / Virus Removal
Need to check system is clean
27 min read
MouxSue
Topic Starter
Hi,
I'm helping a friend with their pc problems. It has been going slow for a long time, sometimes with obvious signs of viruses (spurious pop-ups informing them of a need to buy an anti-virus etc). I recommended they got an antivirus several times, which they now have (AVIRA free edition) and I also downloaded MBAM and Trend Micro Housecall for regular occasional use. These have found and removed/quarantined malware several times but the computer is still very slow and also Firefox ended up with a proxy settings for connecting to the internet. I managed to stop it using this by starting Firefox is safe Mode and selecting no proxy.
I then ran AVIRA in safe mode which detected 63 problems, but I'm still concerned that the system may not be clean (although it is definitely running better) and that the registry will need cleaning up. They also have other problems such as old versions of Norton hanging around although out of date, which we have been unable to delete using Add/Remove Programs (possibly as the result of previous virus removal?). I (and they) would be grateful for some help.
MouxSue
See below for the AVIRA log file:
Avira AntiVir Personal
Report file date: 03 November 2010 12:25
Scanning for 3004805 virus strains and unwanted programs.
The program is running as an unrestricted full version.
Online services are available:
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Safe mode
Username : Administrateur
Computer name : NETWORK_HUB
Version information:
BUILD.DAT : 10.0.0.592 31823 Bytes 09/08/2010 11:00:00
AVSCAN.EXE : 10.0.3.1 434344 Bytes 03/11/2010 08:35:16
AVSCAN.DLL : 10.0.3.0 46440 Bytes 01/04/2010 11:57:04
LUKE.DLL : 10.0.2.3 104296 Bytes 07/03/2010 17:33:04
LUKERES.DLL : 10.0.0.1 12648 Bytes 10/02/2010 22:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 08:05:36
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 18:27:49
VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 16:37:42
VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 15:37:42
VBASE004.VDF : 7.10.4.203 1579008 Bytes 05/03/2010 10:29:03
VBASE005.VDF : 7.10.6.82 2494464 Bytes 15/04/2010 05:19:46
VBASE006.VDF : 7.10.7.218 2294784 Bytes 02/06/2010 05:19:54
VBASE007.VDF : 7.10.9.165 4840960 Bytes 23/07/2010 05:20:03
VBASE008.VDF : 7.10.11.133 3454464 Bytes 13/09/2010 05:20:09
VBASE009.VDF : 7.10.13.80 2265600 Bytes 02/11/2010 08:35:15
VBASE010.VDF : 7.10.13.81 2048 Bytes 02/11/2010 08:35:15
VBASE011.VDF : 7.10.13.82 2048 Bytes 02/11/2010 08:35:15
VBASE012.VDF : 7.10.13.83 2048 Bytes 02/11/2010 08:35:15
VBASE013.VDF : 7.10.13.84 2048 Bytes 02/11/2010 08:35:15
VBASE014.VDF : 7.10.13.85 2048 Bytes 02/11/2010 08:35:15
VBASE015.VDF : 7.10.13.86 2048 Bytes 02/11/2010 08:35:15
VBASE016.VDF : 7.10.13.87 2048 Bytes 02/11/2010 08:35:15
VBASE017.VDF : 7.10.13.88 2048 Bytes 02/11/2010 08:35:15
VBASE018.VDF : 7.10.13.89 2048 Bytes 02/11/2010 08:35:15
VBASE019.VDF : 7.10.13.90 2048 Bytes 02/11/2010 08:35:15
VBASE020.VDF : 7.10.13.91 2048 Bytes 02/11/2010 08:35:15
VBASE021.VDF : 7.10.13.92 2048 Bytes 02/11/2010 08:35:15
VBASE022.VDF : 7.10.13.93 2048 Bytes 02/11/2010 08:35:15
VBASE023.VDF : 7.10.13.94 2048 Bytes 02/11/2010 08:35:15
VBASE024.VDF : 7.10.13.95 2048 Bytes 02/11/2010 08:35:15
VBASE025.VDF : 7.10.13.96 2048 Bytes 02/11/2010 08:35:15
VBASE026.VDF : 7.10.13.97 2048 Bytes 02/11/2010 08:35:15
VBASE027.VDF : 7.10.13.98 2048 Bytes 02/11/2010 08:35:15
VBASE028.VDF : 7.10.13.99 2048 Bytes 02/11/2010 08:35:15
VBASE029.VDF : 7.10.13.100 2048 Bytes 02/11/2010 08:35:15
VBASE030.VDF : 7.10.13.101 2048 Bytes 02/11/2010 08:35:15
VBASE031.VDF : 7.10.13.107 51200 Bytes 02/11/2010 08:35:15
Engineversion : 8.2.4.86
AEVDF.DLL : 8.1.2.1 106868 Bytes 12/10/2010 05:20:27
AESCRIPT.DLL : 8.1.3.45 1368443 Bytes 12/10/2010 05:20:27
AESCN.DLL : 8.1.6.1 127347 Bytes 12/10/2010 05:20:26
AESBX.DLL : 8.1.3.1 254324 Bytes 12/10/2010 05:20:27
AERDL.DLL : 8.1.9.2 635252 Bytes 12/10/2010 05:20:25
AEPACK.DLL : 8.2.3.11 471416 Bytes 12/10/2010 05:20:25
AEOFFICE.DLL : 8.1.1.8 201081 Bytes 12/10/2010 05:20:24
AEHEUR.DLL : 8.1.2.37 2974072 Bytes 03/11/2010 08:35:16
AEHELP.DLL : 8.1.14.0 246134 Bytes 12/10/2010 05:20:21
AEGEN.DLL : 8.1.3.23 401779 Bytes 12/10/2010 05:20:20
AEEMU.DLL : 8.1.2.0 393588 Bytes 12/10/2010 05:20:20
AECORE.DLL : 8.1.17.0 196982 Bytes 12/10/2010 05:20:19
AEBB.DLL : 8.1.1.0 53618 Bytes 12/10/2010 05:20:19
AVWINLL.DLL : 10.0.0.0 19304 Bytes 14/01/2010 11:03:38
AVPREF.DLL : 10.0.0.0 44904 Bytes 14/01/2010 11:03:35
AVREP.DLL : 10.0.0.8 62209 Bytes 18/02/2010 15:47:40
AVREG.DLL : 10.0.3.2 53096 Bytes 03/11/2010 08:35:16
AVSCPLR.DLL : 10.0.3.1 83816 Bytes 03/11/2010 08:35:16
AVARKT.DLL : 10.0.0.14 227176 Bytes 01/04/2010 11:22:13
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 26/01/2010 08:53:30
SQLITE3.DLL : 3.6.19.0 355688 Bytes 28/01/2010 11:57:58
AVSMTP.DLL : 10.0.0.17 63848 Bytes 16/03/2010 14:38:56
NETNT.DLL : 10.0.0.0 11624 Bytes 19/02/2010 13:41:00
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 28/01/2010 12:10:20
RCTEXT.DLL : 10.0.58.0 97128 Bytes 03/11/2010 08:35:15
Configuration settings for the scan:
Jobname………………………..: Complete system scan
Configuration file………………: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp
Logging………………………..: low
Primary action………………….: interactive
Secondary action………………..: ignore
Scan master boot sector………….: on
Scan boot sector………………..: on
Boot sectors……………………: C:, D:,
Process scan……………………: on
Extended process scan……………: on
Scan registry…………………..: on
Search for rootkits……………..: on
Integrity checking of system files..: off
Scan all files………………….: All files
Scan archives…………………..: on
Recursion depth…………………: 20
Smart extensions………………..: on
Macro heuristic…………………: on
File heuristic………………….: medium
Start of the scan: 03 November 2010 12:25
Starting search for hidden objects.
The driver could not be initialized.
The scan of running processes will be started
Scan process 'avscan.exe' - '62' Module(s) have been scanned
Scan process 'avcenter.exe' - '100' Module(s) have been scanned
Scan process 'Explorer.EXE' - '83' Module(s) have been scanned
Scan process 'svchost.exe' - '67' Module(s) have been scanned
Scan process 'svchost.exe' - '40' Module(s) have been scanned
Scan process 'svchost.exe' - '34' Module(s) have been scanned
Scan process 'lsass.exe' - '50' Module(s) have been scanned
Scan process 'services.exe' - '29' Module(s) have been scanned
Scan process 'winlogon.exe' - '61' Module(s) have been scanned
Scan process 'csrss.exe' - '14' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
C:\Program Files\utorrent.exe
[WARNING] The file could not be opened!
The registry was scanned ( '1026' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\3\4e84bf83-49c2cdec
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the JAVA/Agent.J Java virus
–> gogol/Familie.class
[DETECTION] Contains recognition pattern of the JAVA/Agent.J Java virus
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\34db286c-4ecea068
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.AO Java virus
–> Is.class
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.AO Java virus
–> MyName.class
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.AN Java virus
–> Phone.class
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.AP Java virus
C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Windows\shellu.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\Documents and Settings\Propriétaire\Application Data\Sun\Java\Deployment\cache\6.0\19\3ca66313-75ac9c1f
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the JAVA/Beyond.D3 Java virus
–> Matrix.class
[DETECTION] Contains recognition pattern of the JAVA/Beyond.D3 Java virus
C:\Documents and Settings\Propriétaire\Application Data\Sun\Java\Deployment\cache\6.0\63\a0f8dff-1cd5e7d8
[DETECTION] Is the TR/Click.Spyw.b.4.B Trojan
C:\Documents and Settings\Propriétaire\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\BlackBox.class-1d0f4f0d-51173ccb.class
[DETECTION] Is the TR/Click.Spyw.b.4.B Trojan
C:\Documents and Settings\Propriétaire\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv420.jar-960fc21-472e40f2.zip
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the JAVA/Beyond.D3 Java virus
–> Matrix.class
[DETECTION] Contains recognition pattern of the JAVA/Beyond.D3 Java virus
C:\Documents and Settings\Propriétaire\Local Settings\Temp\3hHzLxi0.exe.part
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\Documents and Settings\Propriétaire\Local Settings\Temp\jar_cache6852399107085012120.tmp
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.N Java virus
–> quote/Mailvue.class
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.N Java virus
–> quote/Skypeqd.class
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.S Java virus
–> quote/Twitters.class
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.T Java virus
C:\Documents and Settings\Propriétaire\Local Settings\Temp\jar_cache8724517510925603900.tmp
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the JAVA/Agent.N Java virus
–> AppleT.class
[DETECTION] Contains recognition pattern of the JAVA/Agent.N Java virus
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\9D231514-D297-43E0-AF43-32C2410E65E8\backup\11
[0] Archive type: HIDDEN
[DETECTION] Contains a recognition pattern of the (harmful) BDS/Hupigon.ilxm back-door program
–> FIL\\\?\C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\9D231514-D297-43E0-AF43-32C2410E65E8\backup\11
[DETECTION] Contains a recognition pattern of the (harmful) BDS/Hupigon.ilxm back-door program
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\9D231514-D297-43E0-AF43-32C2410E65E8\backup\20
[0] Archive type: HIDDEN
[DETECTION] Is the TR/Rootkit.Gen3 Trojan
–> FIL\\\?\C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\9D231514-D297-43E0-AF43-32C2410E65E8\backup\20
[DETECTION] Is the TR/Rootkit.Gen3 Trojan
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\9D231514-D297-43E0-AF43-32C2410E65E8\backup\8
[0] Archive type: HIDDEN
[DETECTION] Contains a recognition pattern of the (harmful) BDS/Hupigon.ilxm back-door program
–> FIL\\\?\C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\9D231514-D297-43E0-AF43-32C2410E65E8\backup\8
[DETECTION] Contains a recognition pattern of the (harmful) BDS/Hupigon.ilxm back-door program
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\BEC23BDA-9169-4716-BBDE-A897264D01EA\backup\7
[0] Archive type: HIDDEN
[DETECTION] Is the TR/Rootkit.Gen3 Trojan
–> FIL\\\?\C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\BEC23BDA-9169-4716-BBDE-A897264D01EA\backup\7
[DETECTION] Is the TR/Rootkit.Gen3 Trojan
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\BEC23BDA-9169-4716-BBDE-A897264D01EA\backup\8
[0] Archive type: HIDDEN
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
–> FIL\\\?\C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\BEC23BDA-9169-4716-BBDE-A897264D01EA\backup\8
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\Documents and Settings\Propriétaire\Local Settings\Temp\plugtmp-31\plugin-b3092b4e53ffdefc090bf906e4885a53.pdf
[0] Archive type: PDF Stream
[DETECTION] Contains recognition pattern of the HTML/Malicious.PDF.Gen HTML script virus
–> Object
[DETECTION] Contains recognition pattern of the HTML/Malicious.PDF.Gen HTML script virus
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\avg_avwt_stf_all_8_233a1415_01_net(2).exe.part
[WARNING] The file could not be read!
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\Error.Repair.Professional.v3.9.4.WinAll.Regged-CRD\cnx0785a\cnx0785a.rar
[0] Archive type: RAR
[DETECTION] Is the TR/Agent.199680.H Trojan
–> crd.exe
[DETECTION] Is the TR/Agent.199680.H Trojan
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\ESET.NOD32.Business.Edition.v3.0.672.Incl.Fix-CONDOM\ESET.NOD32.Business.Edition.v3.0.672.Incl\crack\NOD32 FIX.exe
[DETECTION] Is the TR/PSW.Delf.CRW Trojan
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\ESET.NOD32.Business.Edition.v3.0.672.Incl.Fix-CONDOM\ESET.NOD32.Business.Edition.v3.0.672.Incl\nod32v3\crack\NOD32 FIX.exe
[DETECTION] Is the TR/PSW.Delf.CRW Trojan
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\PC.Washer.v2.2.1.build.112008.WinAll.Incl.Keygen-CRD\keygen\keygen.exe
[DETECTION] Is the TR/Sasfis.alry Trojan
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\PC.Washer.v2.2.1.build.112008.WinAll.Incl.Keygen-CRD\PC.Washer.v2.2.1.build.112008.WinAll.Incl\cxg1330a.rar
[0] Archive type: RAR
[DETECTION] Is the TR/Agent.199680.H Trojan
–> crd.exe
[DETECTION] Is the TR/Agent.199680.H Trojan
–> keygen\keygen.exe
[DETECTION] Is the TR/Sasfis.alry Trojan
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\PC.Washer.v2.2.1.build.112008.WinAll.Incl.Keygen-CRD\PC.Washer.v2.2.1.build.112008.WinAll.Incl\keygen\keygen.exe
[DETECTION] Is the TR/Sasfis.alry Trojan
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\Trojan.Remover.v6.7.6.WinALL.Incl.Keygen.and.Patch-BRD\Keygen\Patch.exe
[DETECTION] Is the TR/Spy.45315.2 Trojan
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\TuneUp.Utilities.2009.v8.0.2000.35-TE\Crack\Integrator.exe
[DETECTION] Is the TR/Agent.674048 Trojan
C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\To Copy\International pony\international pony open season.wma
[DETECTION] Is the TR/Dldr.WMA.Wimad.BF Trojan
C:\Documents and Settings\Propriétaire\Mes documents\Programs\BSINSTALL.exe
[DETECTION] Contains recognition pattern of the DR/SaveNow.Z.35 dropper
C:\Program Files\ac3filter_1_11.exe
[WARNING] The file could not be opened!
C:\Program Files\ac3filter_1_46.exe
[WARNING] The file could not be opened!
C:\Program Files\DivXInstaller.exe
[WARNING] The file could not be opened!
C:\Program Files\MP10Setup.exe
[WARNING] The file could not be opened!
C:\Program Files\netsend1.exe
[WARNING] The file could not be opened!
C:\Program Files\Nokia_PC_Suite_rel_7_0_9_2_eng_web.exe
[WARNING] The file could not be opened!
C:\Program Files\Opera_963_en_Setup.exe
[WARNING] The file could not be opened!
C:\Program Files\slsk157NS13c.exe
[WARNING] The file could not be opened!
C:\Program Files\soulseek156c.exe
[WARNING] The file could not be opened!
C:\Program Files\utorrent.exe
[WARNING] The file could not be opened!
C:\Program Files\wmp11-windowsxp-x86-enu.exe
[WARNING] The file could not be opened!
C:\Program Files\APPLICATIONS1\Premiere 5.5\AdobePrem5.5\premiere.r00
[0] Archive type: RAR
[DETECTION] Is the TR/FlashKiller.C Trojan
–> DirectX\ddhelp.exe
[DETECTION] Is the TR/FlashKiller.C Trojan
–> DirectX\dplaysvr.exe
[DETECTION] Is the TR/FlashKiller.C Trojan
–> DirectX\dxinfo.exe
[DETECTION] Contains recognition pattern of the W95/CIH Windows virus
–> DirectX\dxtool.exe
[DETECTION] Is the TR/FlashKiller.C Trojan
C:\Program Files\APPLICATIONS1\Premiere 5.5\AdobePrem5.5\DirectX\dxinfo.exe
[DETECTION] Contains recognition pattern of the W95/CIH Windows virus
C:\Program Files\APPLICATIONS2\CDRWIN\CDRWin 3.8d (with crack).zip
[0] Archive type: ZIP
[DETECTION] Is the TR/PSW.Prast.263 Trojan
–> CDRWIN3.8dEnglish-Fixed-.exe
[DETECTION] Is the TR/PSW.Prast.263 Trojan
C:\Program Files\APPLICATIONS2\nav2001\nav2001.rar
[0] Archive type: RAR
[DETECTION] Is the TR/Dropper.Gen Trojan
–> evc_nav2001.9x.zip
[1] Archive type: ZIP
–> n32userl.dll
–> Object
[DETECTION] Is the TR/Dropper.Gen Trojan
C:\Program Files\APPLICATIONS2\Photoshop6\shk-ps6.zip
[0] Archive type: ZIP
[DETECTION] Is the TR/Agent.782336.D Trojan
–> shock.exe
[DETECTION] Is the TR/Agent.782336.D Trojan
C:\Program Files\APPLICATIONS2\Premiere\premiere.ZIP
[0] Archive type: ZIP
[DETECTION] Is the TR/FlashKiller.C Trojan
–> Adobe Premiere 5.5.r00
[1] Archive type: RAR
–> Adobe Premiere 5.5\DirectX\dplaysvr.exe
[DETECTION] Is the TR/FlashKiller.C Trojan
–> Adobe Premiere 5.5\DirectX\dxinfo.exe
[DETECTION] Contains recognition pattern of the W95/CIH Windows virus
–> Adobe Premiere 5.5\DirectX\dxtool.exe
[DETECTION] Is the TR/FlashKiller.C Trojan
–> Adobe Premiere 5.5\DXMEDIA\DXMEDIA.EXE
[DETECTION] Is the TR/FlashKiller.C Trojan
C:\Program Files\Google\GoogleToolbarNotifier\swg-3.1.807.1746\SearchWithGoogleUpdate.exe
[WARNING] The file could not be opened!
C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll
[WARNING] The file could not be opened!
C:\Program Files\Mozilla Firefox\file.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
C:\Program Files\Photoshop6\shk-ps6.zip
[0] Archive type: ZIP
[DETECTION] Is the TR/Agent.782336.D Trojan
–> shock.exe
[DETECTION] Is the TR/Agent.782336.D Trojan
C:\Program Files\Photoshop6\shk-ps6\shock.exe
[DETECTION] Is the TR/Agent.782336.D Trojan
C:\Program Files\Premiere\premiere.ZIP
[0] Archive type: ZIP
[DETECTION] Is the TR/FlashKiller.C Trojan
–> Adobe Premiere 5.5.r00
[1] Archive type: RAR
–> Adobe Premiere 5.5\DirectX\dplaysvr.exe
[DETECTION] Is the TR/FlashKiller.C Trojan
–> Adobe Premiere 5.5\DirectX\dxinfo.exe
[DETECTION] Contains recognition pattern of the W95/CIH Windows virus
–> Adobe Premiere 5.5\DirectX\dxtool.exe
[DETECTION] Is the TR/FlashKiller.C Trojan
–> Adobe Premiere 5.5\DXMEDIA\DXMEDIA.EXE
[DETECTION] Is the TR/FlashKiller.C Trojan
C:\Program Files\WAREZ\CDRWIN\CDRWin 3.8d (with crack).zip
[0] Archive type: ZIP
[DETECTION] Is the TR/PSW.Prast.263 Trojan
–> CDRWIN3.8dEnglish-Fixed-.exe
[DETECTION] Is the TR/PSW.Prast.263 Trojan
C:\Program Files\WAREZ\nav2001\nav2001.rar
[0] Archive type: RAR
[DETECTION] Is the TR/Dropper.Gen Trojan
–> evc_nav2001.9x.zip
[1] Archive type: ZIP
–> n32userl.dll
–> Object
[DETECTION] Is the TR/Dropper.Gen Trojan
C:\Program Files\WAREZ\Photoshop6\shk-ps6.zip
[0] Archive type: ZIP
[DETECTION] Is the TR/Agent.782336.D Trojan
–> shock.exe
[DETECTION] Is the TR/Agent.782336.D Trojan
C:\Program Files\WAREZ\Premiere\premiere.ZIP
[0] Archive type: ZIP
[DETECTION] Is the TR/FlashKiller.C Trojan
–> Adobe Premiere 5.5.r00
[1] Archive type: RAR
–> Adobe Premiere 5.5\DirectX\dplaysvr.exe
[DETECTION] Is the TR/FlashKiller.C Trojan
–> Adobe Premiere 5.5\DirectX\dxinfo.exe
[DETECTION] Contains recognition pattern of the W95/CIH Windows virus
–> Adobe Premiere 5.5\DirectX\dxtool.exe
[DETECTION] Is the TR/FlashKiller.C Trojan
–> Adobe Premiere 5.5\DXMEDIA\DXMEDIA.EXE
[DETECTION] Is the TR/FlashKiller.C Trojan
C:\WINDOWS\system32\hpzjrd01.dll
[WARNING] The file could not be opened!
C:\WINDOWS\system32\w32n50.dll
[WARNING] The file could not be opened!
C:\WINDOWS\Temp\Acr16C.tmp
[0] Archive type: PDF Stream
[DETECTION] Contains recognition pattern of the EXP/Pidief.15344 exploit
–> Object
[DETECTION] Contains recognition pattern of the EXP/Pidief.15344 exploit
C:\WINDOWS\Temp\Acr18A.tmp
[0] Archive type: PDF Stream
[DETECTION] Contains recognition pattern of the EXP/Pidief.15344 exploit
–> Object
[DETECTION] Contains recognition pattern of the EXP/Pidief.15344 exploit
C:\WINDOWS\Temp\Acr18C.tmp
[0] Archive type: PDF Stream
[DETECTION] Contains recognition pattern of the EXP/Pidief.15344 exploit
–> Object
[DETECTION] Contains recognition pattern of the EXP/Pidief.15344 exploit
C:\WINDOWS\Temp\e.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
–> Object
[DETECTION] Is the TR/Dropper.Gen Trojan
Begin scan in 'D:\'
Beginning disinfection:
C:\WINDOWS\Temp\e.exe
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '4f822b91.qua'.
C:\WINDOWS\Temp\Acr18C.tmp
[DETECTION] Contains recognition pattern of the EXP/Pidief.15344 exploit
[NOTE] The file was moved to the quarantine directory under the name '5760040b.qua'.
C:\WINDOWS\Temp\Acr18A.tmp
[DETECTION] Contains recognition pattern of the EXP/Pidief.15344 exploit
[NOTE] The file was moved to the quarantine directory under the name '053f5ee3.qua'.
C:\WINDOWS\Temp\Acr16C.tmp
[DETECTION] Contains recognition pattern of the EXP/Pidief.15344 exploit
[NOTE] The file was moved to the quarantine directory under the name '63081121.qua'.
C:\Program Files\WAREZ\Premiere\premiere.ZIP
[DETECTION] Is the TR/FlashKiller.C Trojan
[NOTE] The file was moved to the quarantine directory under the name '26f93c6e.qua'.
C:\Program Files\WAREZ\Photoshop6\shk-ps6.zip
[DETECTION] Is the TR/Agent.782336.D Trojan
[NOTE] The file was moved to the quarantine directory under the name '59e80e08.qua'.
C:\Program Files\WAREZ\nav2001\nav2001.rar
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '152b2248.qua'.
C:\Program Files\WAREZ\CDRWIN\CDRWin 3.8d (with crack).zip
[DETECTION] Is the TR/PSW.Prast.263 Trojan
[NOTE] The file was moved to the quarantine directory under the name '69576269.qua'.
C:\Program Files\Premiere\premiere.ZIP
[DETECTION] Is the TR/FlashKiller.C Trojan
[NOTE] The file was moved to the quarantine directory under the name '44184d76.qua'.
C:\Program Files\Photoshop6\shk-ps6\shock.exe
[DETECTION] Is the TR/Agent.782336.D Trojan
[NOTE] The file was moved to the quarantine directory under the name '5d0676e1.qua'.
C:\Program Files\Photoshop6\shk-ps6.zip
[DETECTION] Is the TR/Agent.782336.D Trojan
[NOTE] The file was moved to the quarantine directory under the name '31265ad1.qua'.
C:\Program Files\Mozilla Firefox\file.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '409e6346.qua'.
C:\Program Files\APPLICATIONS2\Premiere\premiere.ZIP
[DETECTION] Is the TR/FlashKiller.C Trojan
[NOTE] The file was moved to the quarantine directory under the name '4e8f539e.qua'.
C:\Program Files\APPLICATIONS2\Photoshop6\shk-ps6.zip
[DETECTION] Is the TR/Agent.782336.D Trojan
[NOTE] The file was moved to the quarantine directory under the name '0bac2ad1.qua'.
C:\Program Files\APPLICATIONS2\nav2001\nav2001.rar
[DETECTION] Is the TR/Dropper.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '02dc2e70.qua'.
C:\Program Files\APPLICATIONS2\CDRWIN\CDRWin 3.8d (with crack).zip
[DETECTION] Is the TR/PSW.Prast.263 Trojan
[NOTE] The file was moved to the quarantine directory under the name '5af9370b.qua'.
C:\Program Files\APPLICATIONS1\Premiere 5.5\AdobePrem5.5\DirectX\dxinfo.exe
[DETECTION] Contains recognition pattern of the W95/CIH Windows virus
[NOTE] The file was moved to the quarantine directory under the name '76144e30.qua'.
C:\Program Files\APPLICATIONS1\Premiere 5.5\AdobePrem5.5\premiere.r00
[DETECTION] Is the TR/FlashKiller.C Trojan
[NOTE] The file was moved to the quarantine directory under the name '48e62eec.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Programs\BSINSTALL.exe
[DETECTION] Contains recognition pattern of the DR/SaveNow.Z.35 dropper
[NOTE] The file was moved to the quarantine directory under the name '2bc4057c.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Ma musique\To Copy\International pony\international pony open season.wma
[DETECTION] Is the TR/Dldr.WMA.Wimad.BF Trojan
[NOTE] The file was moved to the quarantine directory under the name '0d53459d.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\TuneUp.Utilities.2009.v8.0.2000.35-TE\Crack\Integrator.exe
[DETECTION] Is the TR/Agent.674048 Trojan
[NOTE] The file was moved to the quarantine directory under the name '3fc73e27.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\Trojan.Remover.v6.7.6.WinALL.Incl.Keygen.and.Patch-BRD\Keygen\Patch.exe
[DETECTION] Is the TR/Spy.45315.2 Trojan
[NOTE] The file was moved to the quarantine directory under the name '3582154d.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\PC.Washer.v2.2.1.build.112008.WinAll.Incl.Keygen-CRD\PC.Washer.v2.2.1.build.112008.WinAll.Incl\keygen\keygen.exe
[DETECTION] Is the TR/Sasfis.alry Trojan
[NOTE] The file was moved to the quarantine directory under the name '0ade7104.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\PC.Washer.v2.2.1.build.112008.WinAll.Incl.Keygen-CRD\PC.Washer.v2.2.1.build.112008.WinAll.Incl\cxg1330a.rar
[DETECTION] Is the TR/Sasfis.alry Trojan
[NOTE] The file was moved to the quarantine directory under the name '74807d30.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\PC.Washer.v2.2.1.build.112008.WinAll.Incl.Keygen-CRD\keygen\keygen.exe
[DETECTION] Is the TR/Sasfis.alry Trojan
[NOTE] The file was moved to the quarantine directory under the name '218a79e9.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\ESET.NOD32.Business.Edition.v3.0.672.Incl.Fix-CONDOM\ESET.NOD32.Business.Edition.v3.0.672.Incl\nod32v3\crack\NOD32 FIX.exe
[DETECTION] Is the TR/PSW.Delf.CRW Trojan
[NOTE] The file was moved to the quarantine directory under the name '2c43083b.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\ESET.NOD32.Business.Edition.v3.0.672.Incl.Fix-CONDOM\ESET.NOD32.Business.Edition.v3.0.672.Incl\crack\NOD32 FIX.exe
[DETECTION] Is the TR/PSW.Delf.CRW Trojan
[NOTE] The file was moved to the quarantine directory under the name '301e1c35.qua'.
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\Error.Repair.Professional.v3.9.4.WinAll.Regged-CRD\cnx0785a\cnx0785a.rar
[DETECTION] Is the TR/Agent.199680.H Trojan
[NOTE] The file was moved to the quarantine directory under the name '0191511c.qua'.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\plugtmp-31\plugin-b3092b4e53ffdefc090bf906e4885a53.pdf
[DETECTION] Contains recognition pattern of the HTML/Malicious.PDF.Gen HTML script virus
[NOTE] The file was moved to the quarantine directory under the name '6dc8452b.qua'.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\BEC23BDA-9169-4716-BBDE-A897264D01EA\backup\8
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '24556025.qua'.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\BEC23BDA-9169-4716-BBDE-A897264D01EA\backup\7
[DETECTION] Is the TR/Rootkit.Gen3 Trojan
[NOTE] The file was moved to the quarantine directory under the name '7fc068f4.qua'.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\9D231514-D297-43E0-AF43-32C2410E65E8\backup\8
[DETECTION] Contains a recognition pattern of the (harmful) BDS/Hupigon.ilxm back-door program
[NOTE] The file was moved to the quarantine directory under the name '1972641d.qua'.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\9D231514-D297-43E0-AF43-32C2410E65E8\backup\20
[DETECTION] Is the TR/Rootkit.Gen3 Trojan
[NOTE] The file was moved to the quarantine directory under the name '4e9016b9.qua'.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\HouseCall\log\9D231514-D297-43E0-AF43-32C2410E65E8\backup\11
[DETECTION] Contains a recognition pattern of the (harmful) BDS/Hupigon.ilxm back-door program
[NOTE] The file was moved to the quarantine directory under the name '6ce041cd.qua'.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\jar_cache8724517510925603900.tmp
[DETECTION] Contains recognition pattern of the JAVA/Agent.N Java virus
[NOTE] The file was moved to the quarantine directory under the name '049e3b44.qua'.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\jar_cache6852399107085012120.tmp
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.T Java virus
[NOTE] The file was moved to the quarantine directory under the name '24e83fc1.qua'.
C:\Documents and Settings\Propriétaire\Local Settings\Temp\3hHzLxi0.exe.part
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '7196796d.qua'.
C:\Documents and Settings\Propriétaire\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv420.jar-960fc21-472e40f2.zip
[DETECTION] Contains recognition pattern of the JAVA/Beyond.D3 Java virus
[NOTE] The file was moved to the quarantine directory under the name '109d58d5.qua'.
C:\Documents and Settings\Propriétaire\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\BlackBox.class-1d0f4f0d-51173ccb.class
[DETECTION] Is the TR/Click.Spyw.b.4.B Trojan
[NOTE] The file was moved to the quarantine directory under the name '75311a5d.qua'.
C:\Documents and Settings\Propriétaire\Application Data\Sun\Java\Deployment\cache\6.0\63\a0f8dff-1cd5e7d8
[DETECTION] Is the TR/Click.Spyw.b.4.B Trojan
[NOTE] The file was moved to the quarantine directory under the name '10e36e30.qua'.
C:\Documents and Settings\Propriétaire\Application Data\Sun\Java\Deployment\cache\6.0\19\3ca66313-75ac9c1f
[DETECTION] Contains recognition pattern of the JAVA/Beyond.D3 Java virus
[NOTE] The file was moved to the quarantine directory under the name '03025270.qua'.
C:\Documents and Settings\Propriétaire\Application Data\Microsoft\Windows\shellu.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '11bf2ed6.qua'.
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\44\34db286c-4ecea068
[DETECTION] Contains recognition pattern of the JAVA/ClassLoader.AP Java virus
[NOTE] The file was moved to the quarantine directory under the name '06ec4da9.qua'.
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\3\4e84bf83-49c2cdec
[DETECTION] Contains recognition pattern of the JAVA/Agent.J Java virus
[NOTE] The file was moved to the quarantine directory under the name '5cf27fea.qua'.
End of the scan: 03 November 2010 17:34
Used time: 2:48:41 Hour(s)
The scan has been done completely.
10913 Scanned directories
514818 Files were scanned
63 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
44 Files were moved to quarantine
0 Files were renamed
16 Files cannot be scanned
514739 Files not concerned
16247 Archives were scanned
17 Warnings
44 Notes
LDTate
Hello and welcome to the forums
http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Check Remove found threats and Scan potentially unwanted applications.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Check Remove found threats and Scan potentially unwanted applications.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
MouxSue
Hi,
ESET scan done, seems to be more thorough than the Trend Micro Housecall scan which I also did yesterday (before I got your reply) and found nothing.
I haven't deleted anything permanently (either for this scan or the previous AVIRA scan), just left them in quarantine.
Here is the log.txt info:
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=488c05f4bfd0b4418e1b845dae41bd27
# end=stopped
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-11-04 08:25:56
# local_time=2010-11-04 09:25:56 (+0100, Paris, Madrid)
# country="France"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1024 16777215 100 0 53266034 53266034 0 0
# compatibility_mode=1797 16775125 100 93 89440 47952249 82124 0
# compatibility_mode=8192 67108863 100 0 4232 4232 0 0
# scanned=30
# found=0
# cleaned=0
# scan_time=0
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=488c05f4bfd0b4418e1b845dae41bd27
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-11-04 08:46:33
# local_time=2010-11-04 09:46:33 (+0100, Paris, Madrid)
# country="France"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1024 16777215 100 0 53266128 53266128 0 0
# compatibility_mode=1797 16775125 100 93 89534 47952343 82218 0
# compatibility_mode=8192 67108863 100 0 4326 4326 0 0
# scanned=9260
# found=0
# cleaned=0
# scan_time=1149
esets_scanner_update returned -1 esets_gle=53251
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=488c05f4bfd0b4418e1b845dae41bd27
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-11-04 10:39:02
# local_time=2010-11-04 11:39:02 (+0100, Paris, Madrid)
# country="France"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=1024 16777215 100 0 53267322 53267322 0 0
# compatibility_mode=1797 16775125 100 93 90728 47953537 83412 0
# compatibility_mode=8192 67108863 100 0 5520 5520 0 0
# scanned=107652
# found=11
# cleaned=11
# scan_time=6701
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\AVG.Internet.Security.v8.0.233.Incl.Keymaker-EMBRACE\keygen.exe probably a variant of Win32/Agent.EUNMBEJ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Propriétaire\Mes documents\Daniel - Various\DanielFILE\ANTIVIRUS\Dark Riders System Cleaner Pack\ESET.NOD32.Business.Edition.v3.0.672.Incl.Fix-CONDOM\ESET.NOD32.Business.Edition.v3.0.672.Incl\keygen.exe probably a variant of Win32/Agent.EUNMBEJ trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\hp\recovery\wizard\fscommand\AppRecoveryLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\hp\recovery\wizard\fscommand\CDLogic_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\hp\recovery\wizard\fscommand\CreatorLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\hp\recovery\wizard\fscommand\RestoreLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\hp\recovery\wizard\fscommand\RTCDLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\hp\recovery\wizard\fscommand\RunLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\hp\recovery\wizard\fscommand\SysRecoveryLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\hp\recovery\wizard\fscommand\WizardLink_ret.exe probably a variant of Win32/Spy.Agent.BMWSIKB trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files\WAREZ\Zipped\getrt430.exe Win32/Adware.Gator.Trickler application (deleted - quarantined) 00000000000000000000000000000000 C
LDTate
How's it running now?
MouxSue
Hi, Thanks for the quick reply.
It seems to be running fine (but so it did yesterday).
When I just came back to see the results of the ESET scan, there was also a notice from AVIRA saying it detected the following:
Can you help clear up the references to Norton?
I'm also worried about stuff under a particular directory (belonging to my friend's son who comes occasionally) - stuff like uTorrent and Uniblue registry cleaner etc
Regards
It seems to be running fine (but so it did yesterday).
When I just came back to see the results of the ESET scan, there was also a notice from AVIRA saying it detected the following:
Is this a problem?The file 'C:\System Volume Information\_restore{D5798E20-2D90-4B82-81D9-8BCD663C9521}\RP1418\A0533636.exe'
contained a virus or unwanted program 'TR/Dldr.Agent.htx.3' [trojan]
Action(s) taken:
The file was moved to the quarantine directory under the name '4f9c7b58.qua'.
Can you help clear up the references to Norton?
I'm also worried about stuff under a particular directory (belonging to my friend's son who comes occasionally) - stuff like uTorrent and Uniblue registry cleaner etc
Regards
LDTate
Yes, I saw the keygens.
I don't see any refference to Norton's / Symantec.
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
Next:
Download ComboFix from one of these locations:
Link 1
Link 2 If using this link, Right Click and select Save As.
* IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Please do not attach the scan results from Combofx. Use copy/paste.
Also please describe how your computer behaves at the moment.
I don't see any refference to Norton's / Symantec.
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
Next:
Download ComboFix from one of these locations:
Link 1
Link 2 If using this link, Right Click and select Save As.
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
- Double click on ComboFix.exe & follow the prompts.
Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.
Note: If you have SP3, use the SP2 package.
If Vista or Windows 7, skip the Recovery Console part
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Please do not attach the scan results from Combofx. Use copy/paste.
Also please describe how your computer behaves at the moment.
MouxSue
ATF Cleaner done.
Combofix done.
Norton/Symantec is still being loaded up but with errors and appears and disappears from status bar at the bottom.
Combofix log:
ComboFix 10-11-03.04 - Propriétaire 04/11/2010 17:49:13.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.44.1036.18.1023.304 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Security 2006 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Propriétaire\Application Data\download2
c:\windows\system32\drivers\niwjdv.sys
c:\windows\system32\spool\prtprocs\w32x86\CNMPP58.DLL
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_USNJSVC
——-\Service_lkgptq
——-\Service_usnjsvc
((((((((((((((((((((((((( Files Created from 2010-10-04 to 2010-11-04 )))))))))))))))))))))))))))))))
.
2010-11-04 08:15 . 2010-11-04 08:15 ——– d—–w- c:\program files\ESET
2010-11-03 16:49 . 2010-11-03 16:50 ——– d—–w- c:\windows\system32\NtmsData
2010-11-03 08:56 . 2010-11-03 08:56 ——– d—–w- c:\documents and settings\Administrateur
2010-11-02 19:02 . 2010-11-02 19:02 ——– d—–w- c:\documents and settings\Propriétaire\Application Data\Avira
2010-10-12 19:21 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-12 19:21 . 2010-09-18 06:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-12 19:20 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2010-10-12 05:49 . 2010-10-12 05:49 ——– d-sh–w- c:\documents and settings\Propriétaire\IECompatCache
2010-10-12 05:18 . 2010-11-03 08:35 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-12 05:18 . 2010-11-03 08:35 126856 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-12 05:18 . 2009-05-11 10:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-12 05:18 . 2009-05-11 10:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\program files\Avira
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-11 16:26 . 2008-10-23 02:29 14720 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2010-09-18 10:23 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-01-02 02:00 954368 ——w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-01-02 02:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:50 . 2004-01-22 00:27 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:50 . 2004-01-02 02:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:50 . 2004-01-02 01:59 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2004-01-02 01:52 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:55 . 2004-01-01 15:35 1852928 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-01-02 02:02 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2004-01-02 02:01 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2004-01-01 15:35 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2004-01-02 01:58 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2004-01-02 02:01 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:44 . 2004-01-01 09:04 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2009-01-05 13:49 . 2009-01-05 13:49 5619080 -c–a-w- c:\program files\Opera_963_en_Setup.exe
2008-12-29 18:28 . 2008-12-29 18:28 952682 -c–a-w- c:\program files\slsk157NS13c.exe
2008-12-29 18:27 . 2008-12-29 18:27 842672 -c–a-w- c:\program files\soulseek156c.exe
2008-12-23 17:35 . 2008-12-23 17:35 2392722 -c–a-w- c:\program files\ac3filter_1_46.exe
2008-12-23 17:27 . 2008-12-23 17:08 14591176 -c–a-w- c:\program files\DivXInstaller.exe
2008-12-23 17:06 . 2008-12-23 17:06 12754672 -c–a-w- c:\program files\MP10Setup.exe
2008-12-23 16:57 . 2008-12-23 16:56 25740144 -c–a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2008-12-23 16:46 . 2008-12-23 16:46 760708 -c–a-w- c:\program files\ac3filter_1_11.exe
2008-12-11 10:36 . 2008-12-11 10:33 35965184 -c–a-w- c:\program files\Nokia_PC_Suite_rel_7_0_9_2_eng_web.exe
2008-12-11 10:15 . 2008-12-11 10:15 270128 -c–a-w- c:\program files\utorrent.exe
2008-12-09 21:45 . 2008-12-09 21:45 350172 -c–a-w- c:\program files\netsend1.exe
2006-01-26 19:20 . 2005-12-02 17:46 278528 -c–a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
2005-12-25 18:56 . 2005-12-25 18:56 9352392 -c–a-w- c:\program files\Install_MSN_Messenger.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-12 98304]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-02-11 53096]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2006-05-15 67264]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-11-5 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Office\OSA9.EXE [2000-1-21 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\utorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Documents and Settings\\Propriétaire\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/10/2010 06:18 135336]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [20/06/2005 10:12 215040]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/10/2009 13:27 133104]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2010-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-04 c:\windows\Tasks\User_Feed_Synchronization-{6F358112-533C-4437-BEF3-553A9E7C3B55}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: geoportail.fr\www
Trusted Zone: google.fr
FF - ProfilePath - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\lib\WINNT\ff3\AbineComponent.dll
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-WOOKIT - c:\progra~1\Wanadoo\Shell.exe
HKLM-Run-VTTimer - VTTimer.exe
HKLM-Run-WOOWATCH - c:\progra~1\Wanadoo\Watch.exe
HKLM-Run-WOOTASKBARICON - c:\progra~1\Wanadoo\GestMaj.exe
HKLM-Run-SBAutoUpdate - c:\program files\SpywareBlaster\sbautoupdate.exe
HKLM-Run-KBD - c:\hp\KBD\KBD.EXE
HKLM-Run-BearShare - c:\program files\BearShare\BearShare.exe
AddRemove-PowerISO - c:\program files\PowerISO\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-04 17:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asp.net]
"ImagePath"="c:\program files\Common Files\Microsoft Shared\MSINFO\asp.net"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-374452897-3138119479-2366582018-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2672)
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Fichiers communs\Symantec Shared\ccSetMgr.exe
c:\program files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Inventel\Gateway\wlancfg.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\RUNDLL32.EXE
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\Dropbox.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Fichiers communs\Symantec Shared\SNDSrvc.exe
c:\progra~1\FICHIE~1\SYMANT~1\SECURI~1\NSCSRVCE.EXE
.
**************************************************************************
.
Completion time: 2010-11-04 18:08:14 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-04 17:07
Pre-Run: 25 418 551 296 octets libres
Post-Run: 25 664 860 160 octets libres
- - End Of File - - A199126B75714F5387904BB714039857
Combofix done.
Norton/Symantec is still being loaded up but with errors and appears and disappears from status bar at the bottom.
Combofix log:
ComboFix 10-11-03.04 - Propriétaire 04/11/2010 17:49:13.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.44.1036.18.1023.304 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Security 2006 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Propriétaire\Application Data\download2
c:\windows\system32\drivers\niwjdv.sys
c:\windows\system32\spool\prtprocs\w32x86\CNMPP58.DLL
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_USNJSVC
——-\Service_lkgptq
——-\Service_usnjsvc
((((((((((((((((((((((((( Files Created from 2010-10-04 to 2010-11-04 )))))))))))))))))))))))))))))))
.
2010-11-04 08:15 . 2010-11-04 08:15 ——– d—–w- c:\program files\ESET
2010-11-03 16:49 . 2010-11-03 16:50 ——– d—–w- c:\windows\system32\NtmsData
2010-11-03 08:56 . 2010-11-03 08:56 ——– d—–w- c:\documents and settings\Administrateur
2010-11-02 19:02 . 2010-11-02 19:02 ——– d—–w- c:\documents and settings\Propriétaire\Application Data\Avira
2010-10-12 19:21 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-12 19:21 . 2010-09-18 06:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-12 19:20 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2010-10-12 05:49 . 2010-10-12 05:49 ——– d-sh–w- c:\documents and settings\Propriétaire\IECompatCache
2010-10-12 05:18 . 2010-11-03 08:35 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-12 05:18 . 2010-11-03 08:35 126856 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-12 05:18 . 2009-05-11 10:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-12 05:18 . 2009-05-11 10:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\program files\Avira
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-11 16:26 . 2008-10-23 02:29 14720 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2010-09-18 10:23 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-01-02 02:00 954368 ——w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-01-02 02:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:50 . 2004-01-22 00:27 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:50 . 2004-01-02 02:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:50 . 2004-01-02 01:59 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2004-01-02 01:52 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:55 . 2004-01-01 15:35 1852928 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-01-02 02:02 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2004-01-02 02:01 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2004-01-01 15:35 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2004-01-02 01:58 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2004-01-02 02:01 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:44 . 2004-01-01 09:04 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2009-01-05 13:49 . 2009-01-05 13:49 5619080 -c–a-w- c:\program files\Opera_963_en_Setup.exe
2008-12-29 18:28 . 2008-12-29 18:28 952682 -c–a-w- c:\program files\slsk157NS13c.exe
2008-12-29 18:27 . 2008-12-29 18:27 842672 -c–a-w- c:\program files\soulseek156c.exe
2008-12-23 17:35 . 2008-12-23 17:35 2392722 -c–a-w- c:\program files\ac3filter_1_46.exe
2008-12-23 17:27 . 2008-12-23 17:08 14591176 -c–a-w- c:\program files\DivXInstaller.exe
2008-12-23 17:06 . 2008-12-23 17:06 12754672 -c–a-w- c:\program files\MP10Setup.exe
2008-12-23 16:57 . 2008-12-23 16:56 25740144 -c–a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2008-12-23 16:46 . 2008-12-23 16:46 760708 -c–a-w- c:\program files\ac3filter_1_11.exe
2008-12-11 10:36 . 2008-12-11 10:33 35965184 -c–a-w- c:\program files\Nokia_PC_Suite_rel_7_0_9_2_eng_web.exe
2008-12-11 10:15 . 2008-12-11 10:15 270128 -c–a-w- c:\program files\utorrent.exe
2008-12-09 21:45 . 2008-12-09 21:45 350172 -c–a-w- c:\program files\netsend1.exe
2006-01-26 19:20 . 2005-12-02 17:46 278528 -c–a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
2005-12-25 18:56 . 2005-12-25 18:56 9352392 -c–a-w- c:\program files\Install_MSN_Messenger.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-12 98304]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-02-11 53096]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [2006-05-15 67264]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-11-5 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Office\OSA9.EXE [2000-1-21 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\utorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Documents and Settings\\Propriétaire\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/10/2010 06:18 135336]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [20/06/2005 10:12 215040]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/10/2009 13:27 133104]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2010-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-04 c:\windows\Tasks\User_Feed_Synchronization-{6F358112-533C-4437-BEF3-553A9E7C3B55}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: geoportail.fr\www
Trusted Zone: google.fr
FF - ProfilePath - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\lib\WINNT\ff3\AbineComponent.dll
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-WOOKIT - c:\progra~1\Wanadoo\Shell.exe
HKLM-Run-VTTimer - VTTimer.exe
HKLM-Run-WOOWATCH - c:\progra~1\Wanadoo\Watch.exe
HKLM-Run-WOOTASKBARICON - c:\progra~1\Wanadoo\GestMaj.exe
HKLM-Run-SBAutoUpdate - c:\program files\SpywareBlaster\sbautoupdate.exe
HKLM-Run-KBD - c:\hp\KBD\KBD.EXE
HKLM-Run-BearShare - c:\program files\BearShare\BearShare.exe
AddRemove-PowerISO - c:\program files\PowerISO\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-04 17:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asp.net]
"ImagePath"="c:\program files\Common Files\Microsoft Shared\MSINFO\asp.net"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-374452897-3138119479-2366582018-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2672)
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Fichiers communs\Symantec Shared\ccSetMgr.exe
c:\program files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Inventel\Gateway\wlancfg.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\RUNDLL32.EXE
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\Dropbox.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\Fichiers communs\Symantec Shared\SNDSrvc.exe
c:\progra~1\FICHIE~1\SYMANT~1\SECURI~1\NSCSRVCE.EXE
.
**************************************************************************
.
Completion time: 2010-11-04 18:08:14 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-04 17:07
Pre-Run: 25 418 551 296 octets libres
Post-Run: 25 664 860 160 octets libres
- - End Of File - - A199126B75714F5387904BB714039857
LDTate
Open Firefox and do the following:
Go to Tools > Options… > Advanced Icon. Select the Network Tab and under Connections click Settings….
Make sure that the No Proxy radio button is selected, if not you know what to do. This should hopefully solve the problem - let me know if it does.
NexT
Use Add/Remove programs and remove Symantec\LiveUpdate
NexT
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
Also please describe how your computer behaves at the moment.
Go to Tools > Options… > Advanced Icon. Select the Network Tab and under Connections click Settings….
Make sure that the No Proxy radio button is selected, if not you know what to do. This should hopefully solve the problem - let me know if it does.
NexT
Use Add/Remove programs and remove Symantec\LiveUpdate
NexT
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
KillAll:: File:: c:\program files\Fichiers communs\Symantec Shared\SNDSrvc.exe c:\progra~1\FICHIE~1\SYMANT~1\SECURI~1\NSCSRVCE.EXE Folder:: c:\progra~1\SYMNET~1 c:\program files\Fichiers communs\Symantec Shared c:\progra~1\FICHIE~1\SYMANT~1 Registry:: [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ALUAlert"=- "Symantec NetDriver Warning"=- [-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
Also please describe how your computer behaves at the moment.
MouxSue
The machine seems to be running really quickly (loaded up graphics into Paint really quickly, for example), but as it's not my machine, I don't know how bad it was before. It doesn't come up with anything related to Norton any more.
The Combofix log is really long, mainly just all the deletions for symantec - do you really need to see it all? I'm just posting the beginning and end at the moment as I have to go somewhere.
Here's the beginning:
ComboFix 10-11-03.04 - Propriétaire 04/11/2010 19:11:19.2.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.44.1036.18.1023.584 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Bureau\ComboFix.exe
Command switches used :: c:\documents and settings\Propriétaire\Bureau\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Security 2006 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
FILE ::
"c:\progra~1\FICHIE~1\SYMANT~1\SECURI~1\NSCSRVCE.EXE"
"c:\program files\Fichiers communs\Symantec Shared\SNDSrvc.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\progra~1\FICHIE~1\SYMANT~1
and the end:
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_eeCtrl
——-\Legacy_NSCService
——-\Legacy_SNDSrvc
——-\Legacy_eeCtrl
——-\Legacy_NSCService
——-\Legacy_SNDSrvc
——-\Service_eeCtrl
——-\Service_NSCService
——-\Service_SNDSrvc
——-\Service_eeCtrl
——-\Service_NSCService
——-\Service_SNDSrvc
((((((((((((((((((((((((( Files Created from 2010-10-04 to 2010-11-04 )))))))))))))))))))))))))))))))
.
2010-11-04 08:15 . 2010-11-04 08:15 ——– d—–w- c:\program files\ESET
2010-11-03 16:49 . 2010-11-03 16:50 ——– d—–w- c:\windows\system32\NtmsData
2010-11-03 08:56 . 2010-11-03 08:56 ——– d—–w- c:\documents and settings\Administrateur
2010-11-02 19:02 . 2010-11-02 19:02 ——– d—–w- c:\documents and settings\Propriétaire\Application Data\Avira
2010-10-12 19:21 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-12 19:21 . 2010-09-18 06:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-12 19:20 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2010-10-12 05:49 . 2010-10-12 05:49 ——– d-sh–w- c:\documents and settings\Propriétaire\IECompatCache
2010-10-12 05:18 . 2010-11-03 08:35 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-12 05:18 . 2010-11-03 08:35 126856 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-12 05:18 . 2009-05-11 10:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-12 05:18 . 2009-05-11 10:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\program files\Avira
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-11 16:26 . 2008-10-23 02:29 14720 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2010-09-18 10:23 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-01-02 02:00 954368 ——w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-01-02 02:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:50 . 2004-01-22 00:27 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:50 . 2004-01-02 02:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:50 . 2004-01-02 01:59 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2004-01-02 01:52 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:55 . 2004-01-01 15:35 1852928 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-01-02 02:02 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2004-01-02 02:01 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2004-01-01 15:35 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2004-01-02 01:58 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2004-01-02 02:01 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:44 . 2004-01-01 09:04 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2009-01-05 13:49 . 2009-01-05 13:49 5619080 -c–a-w- c:\program files\Opera_963_en_Setup.exe
2008-12-29 18:28 . 2008-12-29 18:28 952682 -c–a-w- c:\program files\slsk157NS13c.exe
2008-12-29 18:27 . 2008-12-29 18:27 842672 -c–a-w- c:\program files\soulseek156c.exe
2008-12-23 17:35 . 2008-12-23 17:35 2392722 -c–a-w- c:\program files\ac3filter_1_46.exe
2008-12-23 17:27 . 2008-12-23 17:08 14591176 -c–a-w- c:\program files\DivXInstaller.exe
2008-12-23 17:06 . 2008-12-23 17:06 12754672 -c–a-w- c:\program files\MP10Setup.exe
2008-12-23 16:57 . 2008-12-23 16:56 25740144 -c–a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2008-12-23 16:46 . 2008-12-23 16:46 760708 -c–a-w- c:\program files\ac3filter_1_11.exe
2008-12-11 10:36 . 2008-12-11 10:33 35965184 -c–a-w- c:\program files\Nokia_PC_Suite_rel_7_0_9_2_eng_web.exe
2008-12-11 10:15 . 2008-12-11 10:15 270128 -c–a-w- c:\program files\utorrent.exe
2008-12-09 21:45 . 2008-12-09 21:45 350172 -c–a-w- c:\program files\netsend1.exe
2006-01-26 19:20 . 2005-12-02 17:46 278528 -c–a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
2005-12-25 18:56 . 2005-12-25 18:56 9352392 -c–a-w- c:\program files\Install_MSN_Messenger.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-12 98304]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-11-5 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Office\OSA9.EXE [2000-1-21 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\utorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Documents and Settings\\Propriétaire\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/10/2010 06:18 135336]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [20/06/2005 10:12 215040]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/10/2009 13:27 133104]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2010-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-04 c:\windows\Tasks\User_Feed_Synchronization-{6F358112-533C-4437-BEF3-553A9E7C3B55}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: geoportail.fr\www
Trusted Zone: google.fr
FF - ProfilePath - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\lib\WINNT\ff3\AbineComponent.dll
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-ccApp - c:\program files\Fichiers communs\Symantec Shared\ccApp.exe
AddRemove-SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20} - c:\program files\Fichiers communs\Symantec Shared\SymSetup\{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-04 19:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asp.net]
"ImagePath"="c:\program files\Common Files\Microsoft Shared\MSINFO\asp.net"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-374452897-3138119479-2366582018-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2232)
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Inventel\Gateway\wlancfg.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\RUNDLL32.EXE
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\Dropbox.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-11-04 19:35:33 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-04 18:35
ComboFix2.txt 2010-11-04 17:08
Pre-Run: 25 910 128 640 octets libres
Post-Run: 25 711 251 456 octets libres
- - End Of File - - AC106CFC5F10F85D38909EC1903F8A70
The Combofix log is really long, mainly just all the deletions for symantec - do you really need to see it all? I'm just posting the beginning and end at the moment as I have to go somewhere.
Here's the beginning:
ComboFix 10-11-03.04 - Propriétaire 04/11/2010 19:11:19.2.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.44.1036.18.1023.584 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Bureau\ComboFix.exe
Command switches used :: c:\documents and settings\Propriétaire\Bureau\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Security 2006 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
FILE ::
"c:\progra~1\FICHIE~1\SYMANT~1\SECURI~1\NSCSRVCE.EXE"
"c:\program files\Fichiers communs\Symantec Shared\SNDSrvc.exe"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\progra~1\FICHIE~1\SYMANT~1
and the end:
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_eeCtrl
——-\Legacy_NSCService
——-\Legacy_SNDSrvc
——-\Legacy_eeCtrl
——-\Legacy_NSCService
——-\Legacy_SNDSrvc
——-\Service_eeCtrl
——-\Service_NSCService
——-\Service_SNDSrvc
——-\Service_eeCtrl
——-\Service_NSCService
——-\Service_SNDSrvc
((((((((((((((((((((((((( Files Created from 2010-10-04 to 2010-11-04 )))))))))))))))))))))))))))))))
.
2010-11-04 08:15 . 2010-11-04 08:15 ——– d—–w- c:\program files\ESET
2010-11-03 16:49 . 2010-11-03 16:50 ——– d—–w- c:\windows\system32\NtmsData
2010-11-03 08:56 . 2010-11-03 08:56 ——– d—–w- c:\documents and settings\Administrateur
2010-11-02 19:02 . 2010-11-02 19:02 ——– d—–w- c:\documents and settings\Propriétaire\Application Data\Avira
2010-10-12 19:21 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-12 19:21 . 2010-09-18 06:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-12 19:20 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2010-10-12 05:49 . 2010-10-12 05:49 ——– d-sh–w- c:\documents and settings\Propriétaire\IECompatCache
2010-10-12 05:18 . 2010-11-03 08:35 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-12 05:18 . 2010-11-03 08:35 126856 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-12 05:18 . 2009-05-11 10:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-12 05:18 . 2009-05-11 10:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\program files\Avira
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-11 16:26 . 2008-10-23 02:29 14720 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2010-09-18 10:23 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-01-02 02:00 954368 ——w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-01-02 02:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:50 . 2004-01-22 00:27 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:50 . 2004-01-02 02:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:50 . 2004-01-02 01:59 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2004-01-02 01:52 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:55 . 2004-01-01 15:35 1852928 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-01-02 02:02 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2004-01-02 02:01 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2004-01-01 15:35 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2004-01-02 01:58 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2004-01-02 02:01 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:44 . 2004-01-01 09:04 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2009-01-05 13:49 . 2009-01-05 13:49 5619080 -c–a-w- c:\program files\Opera_963_en_Setup.exe
2008-12-29 18:28 . 2008-12-29 18:28 952682 -c–a-w- c:\program files\slsk157NS13c.exe
2008-12-29 18:27 . 2008-12-29 18:27 842672 -c–a-w- c:\program files\soulseek156c.exe
2008-12-23 17:35 . 2008-12-23 17:35 2392722 -c–a-w- c:\program files\ac3filter_1_46.exe
2008-12-23 17:27 . 2008-12-23 17:08 14591176 -c–a-w- c:\program files\DivXInstaller.exe
2008-12-23 17:06 . 2008-12-23 17:06 12754672 -c–a-w- c:\program files\MP10Setup.exe
2008-12-23 16:57 . 2008-12-23 16:56 25740144 -c–a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2008-12-23 16:46 . 2008-12-23 16:46 760708 -c–a-w- c:\program files\ac3filter_1_11.exe
2008-12-11 10:36 . 2008-12-11 10:33 35965184 -c–a-w- c:\program files\Nokia_PC_Suite_rel_7_0_9_2_eng_web.exe
2008-12-11 10:15 . 2008-12-11 10:15 270128 -c–a-w- c:\program files\utorrent.exe
2008-12-09 21:45 . 2008-12-09 21:45 350172 -c–a-w- c:\program files\netsend1.exe
2006-01-26 19:20 . 2005-12-02 17:46 278528 -c–a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
2005-12-25 18:56 . 2005-12-25 18:56 9352392 -c–a-w- c:\program files\Install_MSN_Messenger.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-12 98304]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-11-5 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Office\OSA9.EXE [2000-1-21 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\utorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Documents and Settings\\Propriétaire\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/10/2010 06:18 135336]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [20/06/2005 10:12 215040]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/10/2009 13:27 133104]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2010-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-04 c:\windows\Tasks\User_Feed_Synchronization-{6F358112-533C-4437-BEF3-553A9E7C3B55}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: geoportail.fr\www
Trusted Zone: google.fr
FF - ProfilePath - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\lib\WINNT\ff3\AbineComponent.dll
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-ccApp - c:\program files\Fichiers communs\Symantec Shared\ccApp.exe
AddRemove-SymSetup.{A93C9E60-29B6-49da-BA21-F70AC6AADE20} - c:\program files\Fichiers communs\Symantec Shared\SymSetup\{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-04 19:29
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asp.net]
"ImagePath"="c:\program files\Common Files\Microsoft Shared\MSINFO\asp.net"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-374452897-3138119479-2366582018-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(2232)
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Inventel\Gateway\wlancfg.exe
c:\windows\AGRSMMSG.exe
c:\windows\system32\RUNDLL32.EXE
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\Dropbox.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-11-04 19:35:33 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-04 18:35
ComboFix2.txt 2010-11-04 17:08
Pre-Run: 25 910 128 640 octets libres
Post-Run: 25 711 251 456 octets libres
- - End Of File - - AC106CFC5F10F85D38909EC1903F8A70
LDTate
Copy/paste the text in the Codebox below into notepad:
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
Also please describe how your computer behaves at the moment.
Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:
Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.
KillAll:: Firefox:: FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 50370
Save this file to your desktop, Save this as "CFScript"
Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …
[external image: Posted Image]
Drag CFScript.txt into ComboFix.exe
Then post the results log using Copy / Paste
Also please describe how your computer behaves at the moment.
MouxSue
Hi,
I'm back at my own place now, so I'll have to do this tomorrow.
Thanks.
Sue
LDTate
Hi,
I'm back at my own place now, so I'll have to do this tomorrow.
Thanks.
Sue
MouxSue
Hi,
The system is generally running fine. Some problems today (also before I ran Combofix) with internet connection disappearing, but recovers when router rebooted, so i think it may be a France Telecom thing.
Combofix log:
ComboFix 10-11-03.04 - Propriétaire 05/11/2010 10:48:40.3.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.44.1036.18.1023.588 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Bureau\ComboFix.exe
Command switches used :: c:\documents and settings\Propriétaire\Bureau\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Security 2006 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-10-05 to 2010-11-05 )))))))))))))))))))))))))))))))
.
2010-11-04 08:15 . 2010-11-04 08:15 ——– d—–w- c:\program files\ESET
2010-11-03 16:49 . 2010-11-03 16:50 ——– d—–w- c:\windows\system32\NtmsData
2010-11-03 08:56 . 2010-11-03 08:56 ——– d—–w- c:\documents and settings\Administrateur
2010-11-02 19:02 . 2010-11-02 19:02 ——– d—–w- c:\documents and settings\Propriétaire\Application Data\Avira
2010-10-12 19:21 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-12 19:21 . 2010-09-18 06:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-12 19:20 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2010-10-12 05:49 . 2010-10-12 05:49 ——– d-sh–w- c:\documents and settings\Propriétaire\IECompatCache
2010-10-12 05:18 . 2010-11-03 08:35 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-12 05:18 . 2010-11-03 08:35 126856 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-12 05:18 . 2009-05-11 10:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-12 05:18 . 2009-05-11 10:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\program files\Avira
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-11 16:26 . 2008-10-23 02:29 14720 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2010-09-18 10:23 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-01-02 02:00 954368 ——w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-01-02 02:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:50 . 2004-01-22 00:27 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:50 . 2004-01-02 02:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:50 . 2004-01-02 01:59 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2004-01-02 01:52 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:55 . 2004-01-01 15:35 1852928 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-01-02 02:02 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2004-01-02 02:01 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2004-01-01 15:35 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2004-01-02 01:58 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2004-01-02 02:01 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:44 . 2004-01-01 09:04 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2009-01-05 13:49 . 2009-01-05 13:49 5619080 -c–a-w- c:\program files\Opera_963_en_Setup.exe
2008-12-29 18:28 . 2008-12-29 18:28 952682 -c–a-w- c:\program files\slsk157NS13c.exe
2008-12-29 18:27 . 2008-12-29 18:27 842672 -c–a-w- c:\program files\soulseek156c.exe
2008-12-23 17:35 . 2008-12-23 17:35 2392722 -c–a-w- c:\program files\ac3filter_1_46.exe
2008-12-23 17:27 . 2008-12-23 17:08 14591176 -c–a-w- c:\program files\DivXInstaller.exe
2008-12-23 17:06 . 2008-12-23 17:06 12754672 -c–a-w- c:\program files\MP10Setup.exe
2008-12-23 16:57 . 2008-12-23 16:56 25740144 -c–a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2008-12-23 16:46 . 2008-12-23 16:46 760708 -c–a-w- c:\program files\ac3filter_1_11.exe
2008-12-11 10:36 . 2008-12-11 10:33 35965184 -c–a-w- c:\program files\Nokia_PC_Suite_rel_7_0_9_2_eng_web.exe
2008-12-11 10:15 . 2008-12-11 10:15 270128 -c–a-w- c:\program files\utorrent.exe
2008-12-09 21:45 . 2008-12-09 21:45 350172 -c–a-w- c:\program files\netsend1.exe
2006-01-26 19:20 . 2005-12-02 17:46 278528 -c–a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
2005-12-25 18:56 . 2005-12-25 18:56 9352392 -c–a-w- c:\program files\Install_MSN_Messenger.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-12 98304]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-11-5 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Office\OSA9.EXE [2000-1-21 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\utorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Documents and Settings\\Propriétaire\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/10/2010 06:18 135336]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [20/06/2005 10:12 215040]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/10/2009 13:27 133104]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2010-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-05 c:\windows\Tasks\User_Feed_Synchronization-{6F358112-533C-4437-BEF3-553A9E7C3B55}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: geoportail.fr\www
Trusted Zone: google.fr
FF - ProfilePath - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\lib\WINNT\ff3\AbineComponent.dll
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-05 10:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asp.net]
"ImagePath"="c:\program files\Common Files\Microsoft Shared\MSINFO\asp.net"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-374452897-3138119479-2366582018-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3344)
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Inventel\Gateway\wlancfg.exe
c:\windows\AGRSMMSG.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\Dropbox.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-11-05 11:05:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-05 10:05
ComboFix2.txt 2010-11-04 18:35
ComboFix3.txt 2010-11-04 17:08
Pre-Run: 25 688 973 312 octets libres
Post-Run: 25 677 918 208 octets libres
- - End Of File - - 3DA3652E70EA36D97B120A8CBCDE39D8
The system is generally running fine. Some problems today (also before I ran Combofix) with internet connection disappearing, but recovers when router rebooted, so i think it may be a France Telecom thing.
Combofix log:
ComboFix 10-11-03.04 - Propriétaire 05/11/2010 10:48:40.3.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.44.1036.18.1023.588 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Bureau\ComboFix.exe
Command switches used :: c:\documents and settings\Propriétaire\Bureau\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: Norton Internet Security 2006 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2010-10-05 to 2010-11-05 )))))))))))))))))))))))))))))))
.
2010-11-04 08:15 . 2010-11-04 08:15 ——– d—–w- c:\program files\ESET
2010-11-03 16:49 . 2010-11-03 16:50 ——– d—–w- c:\windows\system32\NtmsData
2010-11-03 08:56 . 2010-11-03 08:56 ——– d—–w- c:\documents and settings\Administrateur
2010-11-02 19:02 . 2010-11-02 19:02 ——– d—–w- c:\documents and settings\Propriétaire\Application Data\Avira
2010-10-12 19:21 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-12 19:21 . 2010-09-18 06:53 974848 -c—-w- c:\windows\system32\dllcache\mfc42.dll
2010-10-12 19:20 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2010-10-12 05:49 . 2010-10-12 05:49 ——– d-sh–w- c:\documents and settings\Propriétaire\IECompatCache
2010-10-12 05:18 . 2010-11-03 08:35 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-12 05:18 . 2010-11-03 08:35 126856 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-10-12 05:18 . 2009-05-11 10:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-10-12 05:18 . 2009-05-11 10:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\program files\Avira
2010-10-12 05:18 . 2010-10-12 05:18 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-11 16:26 . 2008-10-23 02:29 14720 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2010-09-18 10:23 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2004-01-02 02:00 974848 —-a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2004-01-02 02:00 954368 ——w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2004-01-02 02:00 953856 —-a-w- c:\windows\system32\mfc40u.dll
2010-09-10 05:50 . 2004-01-22 00:27 916480 —-a-w- c:\windows\system32\wininet.dll
2010-09-10 05:50 . 2004-01-02 02:00 43520 —-a-w- c:\windows\system32\licmgr10.dll
2010-09-10 05:50 . 2004-01-02 01:59 1469440 ——w- c:\windows\system32\inetcpl.cpl
2010-09-01 11:51 . 2004-01-02 01:52 285824 —-a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:55 . 2004-01-01 15:35 1852928 —-a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2004-01-02 02:02 119808 —-a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2004-01-02 02:01 99840 —-a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 05:25 5632 —-a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2004-01-01 15:35 357248 —-a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2004-01-02 01:58 617472 —-a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2004-01-02 02:01 58880 —-a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:44 . 2004-01-01 09:04 590848 —-a-w- c:\windows\system32\rpcrt4.dll
2009-01-05 13:49 . 2009-01-05 13:49 5619080 -c–a-w- c:\program files\Opera_963_en_Setup.exe
2008-12-29 18:28 . 2008-12-29 18:28 952682 -c–a-w- c:\program files\slsk157NS13c.exe
2008-12-29 18:27 . 2008-12-29 18:27 842672 -c–a-w- c:\program files\soulseek156c.exe
2008-12-23 17:35 . 2008-12-23 17:35 2392722 -c–a-w- c:\program files\ac3filter_1_46.exe
2008-12-23 17:27 . 2008-12-23 17:08 14591176 -c–a-w- c:\program files\DivXInstaller.exe
2008-12-23 17:06 . 2008-12-23 17:06 12754672 -c–a-w- c:\program files\MP10Setup.exe
2008-12-23 16:57 . 2008-12-23 16:56 25740144 -c–a-w- c:\program files\wmp11-windowsxp-x86-enu.exe
2008-12-23 16:46 . 2008-12-23 16:46 760708 -c–a-w- c:\program files\ac3filter_1_11.exe
2008-12-11 10:36 . 2008-12-11 10:33 35965184 -c–a-w- c:\program files\Nokia_PC_Suite_rel_7_0_9_2_eng_web.exe
2008-12-11 10:15 . 2008-12-11 10:15 270128 -c–a-w- c:\program files\utorrent.exe
2008-12-09 21:45 . 2008-12-09 21:45 350172 -c–a-w- c:\program files\netsend1.exe
2006-01-26 19:20 . 2005-12-02 17:46 278528 -c–a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
2005-12-25 18:56 . 2005-12-25 18:56 9352392 -c–a-w- c:\program files\Install_MSN_Messenger.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2009-12-09 01:19 94208 —-a-w- c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2003-09-12 98304]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-03 281768]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Dropbox.lnk - c:\documents and settings\Propri‚taire\Application Data\Dropbox\bin\Dropbox.exe [2010-2-26 21979992]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-11-5 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-12 282624]
Microsoft Office.lnk - c:\program files\Office\OSA9.EXE [2000-1-21 65588]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\utorrent.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Spotify\\spotify.exe"=
"c:\\Documents and Settings\\Propriétaire\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/10/2010 06:18 135336]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\drivers\sis163u.sys [20/06/2005 10:12 215040]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [03/10/2009 13:27 133104]
— Other Services/Drivers In Memory —
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
2010-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-03 12:27]
2010-11-05 c:\windows\Tasks\User_Feed_Synchronization-{6F358112-533C-4437-BEF3-553A9E7C3B55}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://google.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: geoportail.fr\www
Trusted Zone: google.fr
FF - ProfilePath - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
FF - prefs.js: network.proxy.type - 0
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\lib\WINNT\ff3\AbineComponent.dll
FF - component: c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\r0qyp5ve.default\extensions\[removed]\components\coolirisstub.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-05 10:57
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\asp.net]
"ImagePath"="c:\program files\Common Files\Microsoft Shared\MSINFO\asp.net"
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-374452897-3138119479-2366582018-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'explorer.exe'(3344)
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\DropboxExt.13.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Inventel\Gateway\wlancfg.exe
c:\windows\AGRSMMSG.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
c:\documents and settings\Propriétaire\Application Data\Dropbox\bin\Dropbox.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Completion time: 2010-11-05 11:05:12 - machine was rebooted
ComboFix-quarantined-files.txt 2010-11-05 10:05
ComboFix2.txt 2010-11-04 18:35
ComboFix3.txt 2010-11-04 17:08
Pre-Run: 25 688 973 312 octets libres
Post-Run: 25 677 918 208 octets libres
- - End Of File - - 3DA3652E70EA36D97B120A8CBCDE39D8
LDTate
I'm not sure why FireFox is using a proxy
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50370
Open Firefox and do the following:
Go to Tools > Options… > Advanced Icon. Select the Network Tab and under Connections click Settings….
Make sure that the No Proxy radio button is selected, if not you know what to do. This should hopefully solve the problem - let me know if it does.
MouxSue
Hi,
I mentioned that I changed the setting to No Proxy in my first post - nothing has changed since, but those values still appeared greyed out under Manual Proxy Configuration. I just tried changing the settings to blank, saved then rechecked the No Proxy option. After restarting Firefox, the values are not shown.
All seems to be working ok.
Is there anything else I need to do / programs I should recommend my friends to uninstall?
Regards,
Sue
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI